Courseiva
OS and Network Forensics →hardMultiple Select

CHFI OS and Network Forensics Practice Question

A security team is analyzing a compromised Linux server. Indicators suggest the attacker used a web shell. Which THREE of the following are common persistence mechanisms that may be found on the system? (Select THREE.)

⚠ Common exam trap

EC-Council often tests cross-platform knowledge by including Windows-specific artifacts (like NTUSER.DAT or Prefetch) in Linux-focused questions, hoping candidates overlook the operating system context and select them out of familiarity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adding an SSH public key to /root/.ssh/authorized_keys

Option A is correct because appending an attacker-controlled public key to /root/.ssh/authorized_keys grants passwordless SSH access as root, a classic Linux persistence technique. Option B is correct because entries added to /etc/crontab (or /etc/cron.d, user crontabs) cause malicious commands or reverse shells to execute on a schedule, surviving reboots. Option E is correct because a malicious unit file placed in /etc/systemd/system/ and enabled with systemctl enable will start the attacker's payload automatically at boot. Option C is incorrect because NTUSER.DAT is a Windows registry hive and does not exist on Linux. Option D is incorrect because Prefetch files are a Windows artifact created by the OS for performance, not a Linux persistence mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Adding an SSH public key to /root/.ssh/authorized_keys

    Why this is correct

    An attacker who gains root access can append a public key to /root/.ssh/authorized_keys, enabling passwordless SSH logins as root indefinitely. This is a low-effort, high-impact persistence mechanism because the legitimate key file already exists and may not trigger immediate alarms. Even if the web shell is patched, the SSH key provides a clean, encrypted backdoor that bypasses normal authentication. Removing it requires auditing the authorized_keys file for unexpected entries.

  • ✓

    Cron jobs added to /etc/crontab

    Why this is correct

    System-wide cron jobs defined in /etc/crontab are executed at scheduled intervals with root privileges. By inserting a line such as `*/5 * * * * root curl ...` an attacker can re-fetch and re-run the web shell payload or execute arbitrary commands, ensuring the backdoor resurfaces after any cleanup. Cron persistence is difficult to spot because the file is a standard system file and the malicious entry can be appended to the end, appearing harmless. It also survives reboots and is independent of systemd service status.

  • ✗

    Modification of the NTUSER.DAT registry hive

    Why it's wrong here

    The NTUSER.DAT registry hive is a component of the Microsoft Windows Registry, storing per-user environment settings and application configurations. A Linux server does not use a registry; its equivalent configuration lives in plain-text files like /etc/passwd, /etc/shadow, and dotfiles under /root. Any modification to NTUSER.DAT would be completely foreign to a Linux forensics examination and provides no persistence for a web shell on a Unix-like system. This option is wrong because it is an artifact from the Windows operating system, not Linux.

  • ✗

    Prefetch file creation

    Why it's wrong here

    Prefetch files are created automatically by Windows to speed up application startup by caching memory-mapped pages, and they are located in C:\Windows\Prefetch. Forensic analysts use them to determine which executables have run on a Windows host, but they do not exist on Linux. A Linux server relies on audit logs like /var/log/audit/audit.log or shell history to track executed commands. Therefore, this option is incorrect for a Linux persistence question.

  • ✓

    A systemd service in /etc/systemd/system/

    Why this is correct

    Systemd unit files placed in /etc/systemd/system/ define persistent services that are launched at boot. An attacker can create a service such as `evil.service` that executes the web shell binary or a reverse shell command, and enable it with `systemctl enable` so it starts automatically. This provides boot persistence and can be configured with `Restart=always` to relaunch the payload if it is killed. It is a common Linux persistence technique that leaves a distinct unit file for investigators to find.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.